Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Quantumcloud ChatbotAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9. | |
| Aplazada | Media (5.3) | 0.47% | — | WP Chatbot FOR MessengerAI | 21/3/2026 | 17/6/2026 | The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the site's MobileMonkey… | |
| Aplazada | Media (5.4) | 0.30% | — | Notchatbot Webchat WidgetAI | 18/3/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered in the chat conversation history. This allows an attacker to inject arbitrary JavaScript code which is executed when the chat history is… | |
| Aplazada | Media (5.3) | 0.32% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 3/3/2026 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.26% | — | Cliengo ChatbotAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cliengo – Chatbot: from n/a through <= 3.0.4. | |
| Aplazada | Media (6.4) | 0.27% | — | Collect.chat Chatbot FOR WordpressAI | 14/2/2026 | 17/6/2026 | The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.28% | — | AYS Code AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files. | |
| Aplazada | Media (6.5) | 0.29% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations… | |
| Aplazada | Media (5.3) | 0.27% | — | Quantumcloud ChatbotAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9. | |
| Aplazada | Media (4.3) | 0.24% | — | Quantumcloud ChatbotAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.7.3. | |
| Aplazada | Media (4.3) | 0.29% | — | Newcodebyte AI Chatbot Free ModelsAI | 24/10/2025 | 30/9/2026 | The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5. This is due to insufficient sanitization in the 'newcodebyte_chatbot_export_messages' function. This makes it possible for unauthenticated… | |
| Analizada | Media (5.3) | 0.19% | — | Oct8ne Chatbot | 22/10/2025 | 17/6/2026 | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as… | |
| Aplazada | Media (5.3) | 0.38% | — | Kognetiks ChatbotAI | 18/10/2025 | 17/6/2026 | The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to upload limited safe files and erase conversations. | |
| Analizada | Media (5.3) | 0.24% | — | Oct8ne Chatbot | 15/10/2025 | 17/6/2026 | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as… | |
| Aplazada | Media (4.3) | 0.27% | — | Quantumcloud ChatbotAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 6.7.3. | |
| Aplazada | Alta (7.5) | 0.77% | — | Quantumcloud ChatbotAI | 25/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot chatbot allows PHP Local File Inclusion.This issue affects ChatBot: from n/a through <= 6.3.5. | |
| Aplazada | Alta (8.8) | 0.85% | — | Deep-diver Llm-as-chatbotAI | 6/2/2025 | 17/6/2026 | An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the modelsbyom.py component. | |
| Aplazada | Media (5.9) | 0.35% | — | Themeisle AI Chatbot FOR Wordpress Hyve LiteAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Stored XSS.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.5) | 0.23% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot conversational-forms allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.23% | — | Aitool Aikct Engine ChatbotAIOpenai ChatgptAIGoogle GeminiAIOpenai Gpt-4oAI+1 | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aitool AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot ai-seo-translator allows Cross Site Request Forgery.This issue affects AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot: from n/a through <= 1.6.2. | |
| Aplazada | Media (5.4) | 0.60% | — | Mobilemonkey Wp-chatbot FOR MessengerAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in MobileMonkey WP-Chatbot for Messenger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Chatbot for Messenger: from n/a through 4.7. | |
| Analizada | Media (4.3) | 0.25% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce validation on the update_assistant, add_new_assistant, and delete_assistant functions. This makes it possible for unauthenticated… | |
| Analizada | Media (6.1) | 0.39% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Media (4.3) | 0.54% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Analizada | Media (4.3) | 0.45% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… |